OJS Website Security Breach – Unauthorized Control and Gambling Content Injection

Dear PKP Team,

We are currently facing a serious security issue with our OJS 3.3 and OJS 3.4. Our website has repeatedly been taken over by unknown parties and turned into an online gambling site.

Problem Description:

  • Our OJS website is frequently hijacked by external actors.

  • The attackers replace our content and use the site for gambling activities.

  • As a temporary solution, we have been deleting suspicious accounts in Google Search Console and resetting ownership verification.

  • Unfortunately, this workaround is not effective, as the problem keeps recurring and has become exhausting to manage.

Request for Support:
We would like to know if there are stronger, more permanent solutions to protect our OJS installation and hosting environment from these types of attacks. Specifically:

  • How can we harden OJS against unauthorized access?

  • Are there recommended server‑level protections or configurations?

  • What best practices should we follow to prevent repeated hijacking?

Any guidance or recommended steps to secure our system would be greatly appreciated.

Thank you

Hi @wahyueko,

You’ll find several posts on this topic:

https://forum.pkp.sfu.ca/search?q=gambling%20order%3Alatest

Often it occurs as a result of not securing one’s site properly:
https://docs.pkp.sfu.ca/admin-guide/en/securing-your-system#security-checklist

I’d encourage you to have a look at some of those posts and make some of the recommended security changes.

-Roger
PKP Team

Hi @wahyueko,

We most commonly see this when users are running out-of-date copies of OJS. Make sure you are up to date with the latest OJS releases for the branch you are using, and then check over Roger’s Admin Guide link above.

Regards,
Alec Smecher
Public Knowledge Project Team